Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7fb7641c71 | ||
|
|
16d6a715a6 | ||
|
|
25da42589e | ||
|
|
f6eb3ece86 | ||
|
|
5cea851e4d | ||
|
|
50a6fec801 | ||
|
|
004dafb228 | ||
|
|
92351b2203 | ||
|
|
c2052fff6a | ||
|
|
081134efb9 | ||
|
|
9a1b671c7a | ||
|
|
ee305bcd3e | ||
|
|
380dd8b313 | ||
|
|
a238b6c08b | ||
|
|
cb8e1437c3 | ||
|
|
f86294bff4 | ||
|
|
2efd71da49 | ||
|
|
7848e8bf27 |
+23
-5
@@ -9,6 +9,9 @@
|
||||
# LTESTS
|
||||
|
||||
config=$1
|
||||
if [ "$config" = "" ]; then
|
||||
config="default"
|
||||
fi
|
||||
|
||||
unset CC CFLAGS CPPFLAGS LDFLAGS LTESTS SUDO
|
||||
|
||||
@@ -108,7 +111,7 @@ case "$config" in
|
||||
kitchensink)
|
||||
CONFIGFLAGS="--with-kerberos5 --with-libedit --with-pam"
|
||||
CONFIGFLAGS="${CONFIGFLAGS} --with-security-key-builtin --with-selinux"
|
||||
CONFIGFLAGS="${CONFIGFLAGS} --with-cflags=-DSK_DEBUG"
|
||||
CFLAGS="-DSK_DEBUG -DSANDBOX_SECCOMP_FILTER_DEBUG"
|
||||
;;
|
||||
hardenedmalloc)
|
||||
CONFIGFLAGS="--with-ldflags=-lhardened_malloc"
|
||||
@@ -141,6 +144,11 @@ case "$config" in
|
||||
;;
|
||||
openssl-*)
|
||||
LIBCRYPTOFLAGS="--with-ssl-dir=/opt/openssl --with-rpath=-Wl,-rpath,"
|
||||
# OpenSSL 1.1.1 specifically has a bug in its RNG that breaks reexec
|
||||
# fallback. See https://bugzilla.mindrot.org/show_bug.cgi?id=3483
|
||||
if [ "$config" = "openssl-1.1.1" ]; then
|
||||
SKIP_LTESTS="reexec"
|
||||
fi
|
||||
;;
|
||||
selinux)
|
||||
CONFIGFLAGS="--with-selinux"
|
||||
@@ -152,7 +160,7 @@ case "$config" in
|
||||
LIBCRYPTOFLAGS="--without-openssl"
|
||||
TEST_TARGET=t-exec
|
||||
;;
|
||||
valgrind-[1-4]|valgrind-unit)
|
||||
valgrind-[1-5]|valgrind-unit)
|
||||
# rlimit sandbox and FORTIFY_SOURCE confuse Valgrind.
|
||||
CONFIGFLAGS="--without-sandbox --without-hardening"
|
||||
CONFIGFLAGS="$CONFIGFLAGS --with-cppflags=-D_FORTIFY_SOURCE=0"
|
||||
@@ -161,16 +169,17 @@ case "$config" in
|
||||
export TEST_SSH_ELAPSED_TIMES
|
||||
# Valgrind slows things down enough that the agent timeout test
|
||||
# won't reliably pass, and the unit tests run longer than allowed
|
||||
# by github so split into three separate tests.
|
||||
tests2="rekey integrity try-ciphers"
|
||||
# by github so split into separate tests.
|
||||
tests2="integrity try-ciphers"
|
||||
tests3="krl forward-control sshsig agent-restrict kextype sftp"
|
||||
tests4="cert-userkey cert-hostkey kextype sftp-perm keygen-comment percent"
|
||||
tests5="rekey"
|
||||
case "$config" in
|
||||
valgrind-1)
|
||||
# All tests except agent-timeout (which is flaky under valgrind)
|
||||
# and hostbased (since valgrind won't let ssh exec keysign).
|
||||
# Slow ones are run separately to increase parallelism.
|
||||
SKIP_LTESTS="agent-timeout hostbased ${tests2} ${tests3} ${tests4}"
|
||||
SKIP_LTESTS="agent-timeout hostbased ${tests2} ${tests3} ${tests4} ${tests5}"
|
||||
;;
|
||||
valgrind-2)
|
||||
LTESTS="${tests2}"
|
||||
@@ -181,6 +190,9 @@ case "$config" in
|
||||
valgrind-4)
|
||||
LTESTS="${tests4}"
|
||||
;;
|
||||
valgrind-5)
|
||||
LTESTS="${tests5}"
|
||||
;;
|
||||
valgrind-unit)
|
||||
TEST_TARGET="unit USE_VALGRIND=1"
|
||||
;;
|
||||
@@ -210,6 +222,10 @@ case "${TARGET_HOST}" in
|
||||
TEST_TARGET="t-exec TEST_SHELL=bash"
|
||||
SKIP_LTESTS="rekey sftp"
|
||||
;;
|
||||
debian-riscv64)
|
||||
# This machine is fairly slow, so skip the unit tests.
|
||||
TEST_TARGET="t-exec"
|
||||
;;
|
||||
dfly58*|dfly60*)
|
||||
# scp 3-way connection hangs on these so skip until sorted.
|
||||
SKIP_LTESTS=scp3
|
||||
@@ -260,6 +276,8 @@ esac
|
||||
case "`./config.guess`" in
|
||||
*cygwin)
|
||||
SUDO=""
|
||||
# Don't run compat tests on cygwin as they don't currently compile.
|
||||
TEST_TARGET="tests"
|
||||
;;
|
||||
*-darwin*)
|
||||
# Unless specified otherwise, build without OpenSSL on Mac OS since
|
||||
|
||||
+77
-76
@@ -2,11 +2,9 @@ name: C/C++ CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ master, ci, V_9_0 ]
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', 'Makefile.in', 'configure.ac' ]
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', '**/Makefile.in', 'configure.ac' ]
|
||||
pull_request:
|
||||
branches: [ master ]
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', 'Makefile.in', 'configure.ac' ]
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', '**/Makefile.in', 'configure.ac' ]
|
||||
|
||||
jobs:
|
||||
ci:
|
||||
@@ -15,104 +13,107 @@ jobs:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# First we test all OSes in the default configuration.
|
||||
os: [ubuntu-20.04, ubuntu-22.04, macos-11, macos-12, windows-2019, windows-2022]
|
||||
configs: [default]
|
||||
target: [ubuntu-20.04, ubuntu-22.04, macos-11, macos-12, windows-2019, windows-2022]
|
||||
config: [default]
|
||||
# Then we include any extra configs we want to test for specific VMs.
|
||||
# Valgrind slows things down quite a bit, so start them first.
|
||||
include:
|
||||
- { os: windows-2019, configs: cygwin-release }
|
||||
- { os: windows-2022, configs: cygwin-release }
|
||||
- { os: ubuntu-20.04, configs: valgrind-1 }
|
||||
- { os: ubuntu-20.04, configs: valgrind-2 }
|
||||
- { os: ubuntu-20.04, configs: valgrind-3 }
|
||||
- { os: ubuntu-20.04, configs: valgrind-4 }
|
||||
- { os: ubuntu-20.04, configs: valgrind-unit }
|
||||
- { os: ubuntu-20.04, configs: c89 }
|
||||
- { os: ubuntu-20.04, configs: clang-6.0 }
|
||||
- { os: ubuntu-20.04, configs: clang-8 }
|
||||
- { os: ubuntu-20.04, configs: clang-9 }
|
||||
- { os: ubuntu-20.04, configs: clang-10 }
|
||||
- { os: ubuntu-20.04, configs: clang-11 }
|
||||
- { os: ubuntu-20.04, configs: clang-12-Werror }
|
||||
- { os: ubuntu-20.04, configs: clang-sanitize-address }
|
||||
- { os: ubuntu-20.04, configs: clang-sanitize-undefined }
|
||||
- { os: ubuntu-20.04, configs: gcc-sanitize-address }
|
||||
- { os: ubuntu-20.04, configs: gcc-sanitize-undefined }
|
||||
- { os: ubuntu-20.04, configs: gcc-7 }
|
||||
- { os: ubuntu-20.04, configs: gcc-8 }
|
||||
- { os: ubuntu-20.04, configs: gcc-10 }
|
||||
- { os: ubuntu-20.04, configs: gcc-11-Werror }
|
||||
- { os: ubuntu-20.04, configs: pam }
|
||||
- { os: ubuntu-20.04, configs: kitchensink }
|
||||
- { os: ubuntu-20.04, configs: hardenedmalloc }
|
||||
- { os: ubuntu-20.04, configs: tcmalloc }
|
||||
- { os: ubuntu-20.04, configs: musl }
|
||||
- { os: ubuntu-latest, configs: libressl-master }
|
||||
- { os: ubuntu-latest, configs: libressl-2.2.9 }
|
||||
- { os: ubuntu-latest, configs: libressl-2.8.3 }
|
||||
- { os: ubuntu-latest, configs: libressl-3.0.2 }
|
||||
- { os: ubuntu-latest, configs: libressl-3.2.6 }
|
||||
- { os: ubuntu-latest, configs: libressl-3.3.6 }
|
||||
- { os: ubuntu-latest, configs: libressl-3.4.3 }
|
||||
- { os: ubuntu-latest, configs: libressl-3.5.3 }
|
||||
- { os: ubuntu-latest, configs: openssl-master }
|
||||
- { os: ubuntu-latest, configs: openssl-noec }
|
||||
- { os: ubuntu-latest, configs: openssl-1.0.1 }
|
||||
- { os: ubuntu-latest, configs: openssl-1.0.1u }
|
||||
- { os: ubuntu-latest, configs: openssl-1.0.2u }
|
||||
- { os: ubuntu-latest, configs: openssl-1.1.0h }
|
||||
- { os: ubuntu-latest, configs: openssl-1.1.1 }
|
||||
- { os: ubuntu-latest, configs: openssl-1.1.1k }
|
||||
- { os: ubuntu-latest, configs: openssl-1.1.1n }
|
||||
- { os: ubuntu-latest, configs: openssl-1.1.1p }
|
||||
- { os: ubuntu-latest, configs: openssl-3.0.0 }
|
||||
- { os: ubuntu-latest, configs: openssl-3.0.5 }
|
||||
- { os: ubuntu-latest, configs: openssl-1.1.1_stable } # stable branch
|
||||
- { os: ubuntu-latest, configs: openssl-3.0 } # stable branch
|
||||
- { os: ubuntu-22.04, configs: pam }
|
||||
- { os: ubuntu-22.04, configs: krb5 }
|
||||
- { os: ubuntu-22.04, configs: heimdal }
|
||||
- { os: ubuntu-22.04, configs: libedit }
|
||||
- { os: ubuntu-22.04, configs: sk }
|
||||
- { os: ubuntu-22.04, configs: selinux }
|
||||
- { os: ubuntu-22.04, configs: kitchensink }
|
||||
- { os: ubuntu-22.04, configs: without-openssl }
|
||||
- { os: macos-11, configs: pam }
|
||||
- { os: macos-12, configs: pam }
|
||||
runs-on: ${{ matrix.os }}
|
||||
- { target: windows-2019, config: cygwin-release }
|
||||
- { target: windows-2022, config: cygwin-release }
|
||||
- { target: ubuntu-20.04, config: valgrind-1 }
|
||||
- { target: ubuntu-20.04, config: valgrind-2 }
|
||||
- { target: ubuntu-20.04, config: valgrind-3 }
|
||||
- { target: ubuntu-20.04, config: valgrind-4 }
|
||||
- { target: ubuntu-20.04, config: valgrind-5 }
|
||||
- { target: ubuntu-20.04, config: valgrind-unit }
|
||||
- { target: ubuntu-20.04, config: c89 }
|
||||
- { target: ubuntu-20.04, config: clang-6.0 }
|
||||
- { target: ubuntu-20.04, config: clang-8 }
|
||||
- { target: ubuntu-20.04, config: clang-9 }
|
||||
- { target: ubuntu-20.04, config: clang-10 }
|
||||
- { target: ubuntu-20.04, config: clang-11 }
|
||||
- { target: ubuntu-20.04, config: clang-12-Werror }
|
||||
- { target: ubuntu-20.04, config: clang-sanitize-address }
|
||||
- { target: ubuntu-20.04, config: clang-sanitize-undefined }
|
||||
- { target: ubuntu-20.04, config: gcc-sanitize-address }
|
||||
- { target: ubuntu-20.04, config: gcc-sanitize-undefined }
|
||||
- { target: ubuntu-20.04, config: gcc-7 }
|
||||
- { target: ubuntu-20.04, config: gcc-8 }
|
||||
- { target: ubuntu-20.04, config: gcc-10 }
|
||||
- { target: ubuntu-20.04, config: gcc-11-Werror }
|
||||
- { target: ubuntu-20.04, config: pam }
|
||||
- { target: ubuntu-20.04, config: kitchensink }
|
||||
- { target: ubuntu-20.04, config: hardenedmalloc }
|
||||
- { target: ubuntu-20.04, config: tcmalloc }
|
||||
- { target: ubuntu-20.04, config: musl }
|
||||
- { target: ubuntu-latest, config: libressl-master }
|
||||
- { target: ubuntu-latest, config: libressl-2.2.9 }
|
||||
- { target: ubuntu-latest, config: libressl-2.8.3 }
|
||||
- { target: ubuntu-latest, config: libressl-3.0.2 }
|
||||
- { target: ubuntu-latest, config: libressl-3.2.6 }
|
||||
- { target: ubuntu-latest, config: libressl-3.3.6 }
|
||||
- { target: ubuntu-latest, config: libressl-3.4.3 }
|
||||
- { target: ubuntu-latest, config: libressl-3.5.3 }
|
||||
- { target: ubuntu-latest, config: libressl-3.6.1 }
|
||||
- { target: ubuntu-latest, config: openssl-master }
|
||||
- { target: ubuntu-latest, config: openssl-noec }
|
||||
- { target: ubuntu-latest, config: openssl-1.0.1 }
|
||||
- { target: ubuntu-latest, config: openssl-1.0.1u }
|
||||
- { target: ubuntu-latest, config: openssl-1.0.2u }
|
||||
- { target: ubuntu-latest, config: openssl-1.1.0h }
|
||||
- { target: ubuntu-latest, config: openssl-1.1.1 }
|
||||
- { target: ubuntu-latest, config: openssl-1.1.1k }
|
||||
- { target: ubuntu-latest, config: openssl-1.1.1n }
|
||||
- { target: ubuntu-latest, config: openssl-1.1.1q }
|
||||
- { target: ubuntu-latest, config: openssl-3.0.0 }
|
||||
- { target: ubuntu-latest, config: openssl-3.0.5 }
|
||||
- { target: ubuntu-latest, config: openssl-3.0.7 }
|
||||
- { target: ubuntu-latest, config: openssl-1.1.1_stable }
|
||||
- { target: ubuntu-latest, config: openssl-3.0 } # stable branch
|
||||
- { target: ubuntu-22.04, config: pam }
|
||||
- { target: ubuntu-22.04, config: krb5 }
|
||||
- { target: ubuntu-22.04, config: heimdal }
|
||||
- { target: ubuntu-22.04, config: libedit }
|
||||
- { target: ubuntu-22.04, config: sk }
|
||||
- { target: ubuntu-22.04, config: selinux }
|
||||
- { target: ubuntu-22.04, config: kitchensink }
|
||||
- { target: ubuntu-22.04, config: without-openssl }
|
||||
- { target: macos-11, config: pam }
|
||||
- { target: macos-12, config: pam }
|
||||
runs-on: ${{ matrix.target }}
|
||||
steps:
|
||||
- name: set cygwin git params
|
||||
if: ${{ startsWith(matrix.os, 'windows') }}
|
||||
if: ${{ startsWith(matrix.target, 'windows') }}
|
||||
run: git config --global core.autocrlf input
|
||||
- name: install cygwin
|
||||
if: ${{ startsWith(matrix.os, 'windows') }}
|
||||
if: ${{ startsWith(matrix.target, 'windows') }}
|
||||
uses: cygwin/cygwin-install-action@master
|
||||
- uses: actions/checkout@v2
|
||||
- uses: actions/checkout@main
|
||||
- name: setup CI system
|
||||
run: sh ./.github/setup_ci.sh ${{ matrix.configs }}
|
||||
run: sh ./.github/setup_ci.sh ${{ matrix.config }}
|
||||
- name: autoreconf
|
||||
run: sh -c autoreconf
|
||||
- name: configure
|
||||
run: sh ./.github/configure.sh ${{ matrix.configs }}
|
||||
run: sh ./.github/configure.sh ${{ matrix.config }}
|
||||
- name: save config
|
||||
uses: actions/upload-artifact@v2
|
||||
uses: actions/upload-artifact@main
|
||||
with:
|
||||
name: ${{ matrix.os }}-${{ matrix.configs }}-config
|
||||
name: ${{ matrix.target }}-${{ matrix.config }}-config
|
||||
path: config.h
|
||||
- name: make clean
|
||||
run: make clean
|
||||
- name: make
|
||||
run: make -j2
|
||||
- name: make tests
|
||||
run: sh ./.github/run_test.sh ${{ matrix.configs }}
|
||||
run: sh ./.github/run_test.sh ${{ matrix.config }}
|
||||
env:
|
||||
TEST_SSH_UNSAFE_PERMISSIONS: 1
|
||||
TEST_SSH_HOSTBASED_AUTH: yes
|
||||
- name: save logs
|
||||
if: failure()
|
||||
uses: actions/upload-artifact@v2
|
||||
uses: actions/upload-artifact@main
|
||||
with:
|
||||
name: ${{ matrix.os }}-${{ matrix.configs }}-logs
|
||||
name: ${{ matrix.target }}-${{ matrix.config }}-logs
|
||||
path: |
|
||||
config.h
|
||||
config.log
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
name: CIFuzz
|
||||
on:
|
||||
push:
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', '**/Makefile.in', 'configure.ac' ]
|
||||
pull_request:
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', '**/Makefile.in', 'configure.ac' ]
|
||||
|
||||
jobs:
|
||||
Fuzzing:
|
||||
if: github.repository != 'openssh/openssh-portable-selfhosted'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Build Fuzzers
|
||||
id: build
|
||||
uses: google/oss-fuzz/infra/cifuzz/actions/build_fuzzers@master
|
||||
with:
|
||||
oss-fuzz-project-name: 'openssh'
|
||||
dry-run: false
|
||||
language: c++
|
||||
- name: Run Fuzzers
|
||||
uses: google/oss-fuzz/infra/cifuzz/actions/run_fuzzers@master
|
||||
with:
|
||||
oss-fuzz-project-name: 'openssh'
|
||||
fuzz-seconds: 600
|
||||
dry-run: false
|
||||
language: c++
|
||||
- name: Upload Crash
|
||||
uses: actions/upload-artifact@main
|
||||
if: failure() && steps.build.outcome == 'success'
|
||||
with:
|
||||
name: artifacts
|
||||
path: ./out/artifacts
|
||||
@@ -2,37 +2,35 @@ name: C/C++ CI self-hosted
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ master, ci, V_9_0 ]
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', 'Makefile.in', 'configure.ac' ]
|
||||
paths: [ '**.c', '**.h', '**.m4', '**.sh', '.github/**', '**/Makefile.in', 'configure.ac' ]
|
||||
|
||||
jobs:
|
||||
selfhosted:
|
||||
if: github.repository == 'openssh/openssh-portable-selfhosted'
|
||||
runs-on: ${{ matrix.os }}
|
||||
runs-on: ${{ matrix.host }}
|
||||
timeout-minutes: 600
|
||||
env:
|
||||
TARGET_HOST: ${{ matrix.os }}
|
||||
HOST: ${{ matrix.host }}
|
||||
TARGET_HOST: ${{ matrix.target }}
|
||||
TARGET_CONFIG: ${{ matrix.config }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
# We use a matrix in two parts: firstly all of the VMs are tested with the
|
||||
# default config. "os" corresponds to a label associated with the worker.
|
||||
# default config. "target" corresponds to a label associated with the
|
||||
# worker. The default is an ephemeral VM running under libvirt.
|
||||
matrix:
|
||||
os:
|
||||
- aix51
|
||||
- ARM
|
||||
- ARM64
|
||||
target:
|
||||
- alpine
|
||||
- debian-i386
|
||||
- debian-riscv64
|
||||
- dfly30
|
||||
- dfly48
|
||||
- dfly58
|
||||
- dfly60
|
||||
- dfly62
|
||||
- fbsd10
|
||||
- fbsd12
|
||||
- fbsd13
|
||||
# - hurd
|
||||
- minix3
|
||||
# - nbsd2
|
||||
- nbsd3
|
||||
- nbsd4
|
||||
- nbsd8
|
||||
@@ -42,62 +40,71 @@ jobs:
|
||||
- obsd69
|
||||
- obsd70
|
||||
- obsdsnap
|
||||
- obsdsnap-i386
|
||||
- openindiana
|
||||
- openwrt-mips
|
||||
- openwrt-mipsel
|
||||
# - rocky84
|
||||
- sol10
|
||||
- sol11
|
||||
- win10
|
||||
configs:
|
||||
config:
|
||||
- default
|
||||
# Then we include any extra configs we want to test for specific VMs.
|
||||
host:
|
||||
- libvirt
|
||||
include:
|
||||
- { os: ARM64, configs: pam }
|
||||
- { os: debian-i386, configs: pam }
|
||||
- { os: dfly30, configs: without-openssl}
|
||||
- { os: dfly48, configs: pam }
|
||||
- { os: dfly58, configs: pam }
|
||||
- { os: dfly60, configs: pam }
|
||||
- { os: fbsd10, configs: pam }
|
||||
- { os: fbsd12, configs: pam }
|
||||
- { os: fbsd13, configs: pam }
|
||||
- { os: nbsd8, configs: pam }
|
||||
- { os: nbsd9, configs: pam }
|
||||
- { os: openindiana, configs: pam }
|
||||
# - { os: rocky84, configs: pam }
|
||||
- { os: sol10, configs: pam }
|
||||
- { os: sol11, configs: pam-krb5 }
|
||||
- { os: sol11, configs: sol64 }
|
||||
# - { os: sol11, configs: sol64-pam }
|
||||
- { os: win10, configs: cygwin-release }
|
||||
# Then we include extra libvirt test configs.
|
||||
- { target: aix51, config: default, host: libvirt }
|
||||
- { target: debian-i386, config: pam, host: libvirt }
|
||||
- { target: dfly30, config: without-openssl, host: libvirt}
|
||||
- { target: dfly48, config: pam ,host: libvirt }
|
||||
- { target: dfly58, config: pam, host: libvirt }
|
||||
- { target: dfly60, config: pam, host: libvirt }
|
||||
- { target: dfly62, config: pam, host: libvirt }
|
||||
- { target: fbsd10, config: pam, host: libvirt }
|
||||
- { target: fbsd12, config: pam, host: libvirt }
|
||||
- { target: fbsd13, config: pam, host: libvirt }
|
||||
- { target: nbsd8, config: pam, host: libvirt }
|
||||
- { target: nbsd9, config: pam, host: libvirt }
|
||||
- { target: openindiana, config: pam, host: libvirt }
|
||||
- { target: sol10, config: pam, host: libvirt }
|
||||
- { target: sol11, config: pam-krb5, host: libvirt }
|
||||
- { target: sol11, config: sol64, host: libvirt }
|
||||
# VMs with persistent disks that have their own runner.
|
||||
- { target: win10, config: default, host: win10 }
|
||||
- { target: win10, config: cygwin-release, host: win10 }
|
||||
# Physical hosts, with either native runners or remote via ssh.
|
||||
- { target: ARM, config: default, host: ARM }
|
||||
- { target: ARM64, config: default, host: ARM64 }
|
||||
- { target: ARM64, config: pam, host: ARM64 }
|
||||
- { target: debian-riscv64, config: default, host: debian-riscv64 }
|
||||
- { target: openwrt-mips, config: default, host: openwrt-mips }
|
||||
- { target: openwrt-mipsel, config: default, host: openwrt-mipsel }
|
||||
steps:
|
||||
- name: shutdown VM if running
|
||||
run: vmshutdown
|
||||
- uses: actions/checkout@v2
|
||||
working-directory: ${{ runner.temp }}
|
||||
- uses: actions/checkout@main
|
||||
- name: autoreconf
|
||||
run: autoreconf
|
||||
- name: startup VM
|
||||
run: vmstartup
|
||||
working-directory: ${{ runner.temp }}
|
||||
- name: configure
|
||||
run: vmrun ./.github/configure.sh ${{ matrix.configs }}
|
||||
run: vmrun ./.github/configure.sh ${{ matrix.config }}
|
||||
- name: save config
|
||||
uses: actions/upload-artifact@v2
|
||||
uses: actions/upload-artifact@main
|
||||
with:
|
||||
name: ${{ matrix.os }}-${{ matrix.configs }}-config
|
||||
name: ${{ matrix.target }}-${{ matrix.config }}-config
|
||||
path: config.h
|
||||
- name: make clean
|
||||
run: vmrun make clean
|
||||
- name: make
|
||||
run: vmrun make
|
||||
- name: make tests
|
||||
run: vmrun ./.github/run_test.sh ${{ matrix.configs }}
|
||||
run: vmrun ./.github/run_test.sh ${{ matrix.config }}
|
||||
timeout-minutes: 600
|
||||
- name: save logs
|
||||
if: failure()
|
||||
uses: actions/upload-artifact@v2
|
||||
uses: actions/upload-artifact@main
|
||||
with:
|
||||
name: ${{ matrix.os }}-${{ matrix.configs }}-logs
|
||||
name: ${{ matrix.target }}-${{ matrix.config }}-logs
|
||||
path: |
|
||||
config.h
|
||||
config.log
|
||||
@@ -106,3 +113,4 @@ jobs:
|
||||
- name: shutdown VM
|
||||
if: always()
|
||||
run: vmshutdown
|
||||
working-directory: ${{ runner.temp }}
|
||||
|
||||
@@ -2,46 +2,51 @@ name: Upstream self-hosted
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ master, ci ]
|
||||
branches: [ master ]
|
||||
paths: [ '**.c', '**.h', '.github/**' ]
|
||||
|
||||
jobs:
|
||||
selfhosted:
|
||||
if: github.repository == 'openssh/openssh-portable-selfhosted'
|
||||
runs-on: ${{ matrix.os }}
|
||||
runs-on: 'libvirt'
|
||||
env:
|
||||
TARGET_HOST: ${{ matrix.os }}
|
||||
HOST: 'libvirt'
|
||||
TARGET_HOST: ${{ matrix.target }}
|
||||
TARGET_CONFIG: ${{ matrix.config }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [ obsdsnap, obsdsnap-i386 ]
|
||||
configs: [ default, without-openssl, ubsan ]
|
||||
target: [ obsdsnap, obsdsnap-i386 ]
|
||||
config: [ default, without-openssl, ubsan ]
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- name: shutdown VM if running
|
||||
run: vmshutdown
|
||||
working-directory: ${{ runner.temp }}
|
||||
- uses: actions/checkout@main
|
||||
- name: startup VM
|
||||
run: vmstartup
|
||||
working-directory: ${{ runner.temp }}
|
||||
- name: update source
|
||||
run: vmrun "cd /usr/src && cvs up -dPA usr.bin/ssh regress/usr.bin/ssh"
|
||||
- name: make clean
|
||||
run: vmrun "cd /usr/src/usr.bin/ssh && make obj && make clean && cd /usr/src/regress/usr.bin/ssh && make obj && make clean"
|
||||
- name: make
|
||||
run: vmrun "cd /usr/src/usr.bin/ssh && case ${{ matrix.configs }} in without-openssl) make OPENSSL=no;; ubsan) make DEBUG='-fsanitize-minimal-runtime -fsanitize=undefined';; *) make; esac"
|
||||
run: vmrun "cd /usr/src/usr.bin/ssh && case ${{ matrix.config }} in without-openssl) make OPENSSL=no;; ubsan) make DEBUG='-fsanitize-minimal-runtime -fsanitize=undefined';; *) make; esac"
|
||||
- name: make install
|
||||
run: vmrun "cd /usr/src/usr.bin/ssh && sudo make install"
|
||||
- name: make tests`
|
||||
run: vmrun "cd /usr/src/regress/usr.bin/ssh && case ${{ matrix.configs }} in without-openssl) make OPENSSL=no;; ubsan) make DEBUG='-fsanitize-minimal-runtime -fsanitize=undefined';; *) make; esac"
|
||||
run: vmrun "cd /usr/src/regress/usr.bin/ssh && case ${{ matrix.config }} in without-openssl) make OPENSSL=no;; ubsan) make DEBUG='-fsanitize-minimal-runtime -fsanitize=undefined';; *) make; esac"
|
||||
env:
|
||||
SUDO: sudo
|
||||
timeout-minutes: 300
|
||||
- name: save logs
|
||||
if: failure()
|
||||
uses: actions/upload-artifact@v2
|
||||
uses: actions/upload-artifact@main
|
||||
with:
|
||||
name: ${{ matrix.os }}-${{ matrix.configs }}-logs
|
||||
name: ${{ matrix.target }}-${{ matrix.config }}-logs
|
||||
path: |
|
||||
/usr/obj/regress/usr.bin/ssh/*.log
|
||||
- name: shutdown VM
|
||||
if: always()
|
||||
run: vmshutdown
|
||||
working-directory: ${{ runner.temp }}
|
||||
|
||||
+27
-16
@@ -172,6 +172,22 @@ AC_COMPILE_IFELSE([AC_LANG_SOURCE([[int main(void) { return 0; }]])],
|
||||
CFLAGS="$saved_CFLAGS"
|
||||
|
||||
if test "$GCC" = "yes" || test "$GCC" = "egcs"; then
|
||||
AC_MSG_CHECKING([gcc version])
|
||||
GCC_VER=`$CC -v 2>&1 | $AWK '/gcc version /{print $3}'`
|
||||
case "$GCC_VER" in
|
||||
1.*) no_attrib_nonnull=1 ;;
|
||||
2.8* | 2.9*)
|
||||
no_attrib_nonnull=1
|
||||
;;
|
||||
2.*) no_attrib_nonnull=1 ;;
|
||||
*) ;;
|
||||
esac
|
||||
AC_MSG_RESULT([$GCC_VER])
|
||||
|
||||
AC_MSG_CHECKING([clang version])
|
||||
CLANG_VER=`$CC -v 2>&1 | $AWK '/clang version /{print $3}'`
|
||||
AC_MSG_RESULT([$CLANG_VER])
|
||||
|
||||
OSSH_CHECK_CFLAG_COMPILE([-pipe])
|
||||
OSSH_CHECK_CFLAG_COMPILE([-Wunknown-warning-option])
|
||||
OSSH_CHECK_CFLAG_COMPILE([-Wno-error=format-truncation])
|
||||
@@ -203,20 +219,15 @@ if test "$GCC" = "yes" || test "$GCC" = "egcs"; then
|
||||
# actually links. The test program compiled/linked includes a number
|
||||
# of integer operations that should exercise this.
|
||||
OSSH_CHECK_CFLAG_LINK([-ftrapv])
|
||||
OSSH_CHECK_CFLAG_COMPILE([-fzero-call-used-regs=all])
|
||||
# clang 15 seems to have a big in -fzero-call-used-regs=all. See
|
||||
# https://bugzilla.mindrot.org/show_bug.cgi?id=3475 and
|
||||
# https://github.com/llvm/llvm-project/issues/59242
|
||||
case "$CLANG_VER" in
|
||||
15.*) OSSH_CHECK_CFLAG_COMPILE([-fzero-call-used-regs=used]) ;;
|
||||
*) OSSH_CHECK_CFLAG_COMPILE([-fzero-call-used-regs=all]) ;;
|
||||
esac
|
||||
OSSH_CHECK_CFLAG_COMPILE([-ftrivial-auto-var-init=zero])
|
||||
fi
|
||||
AC_MSG_CHECKING([gcc version])
|
||||
GCC_VER=`$CC -v 2>&1 | $AWK '/gcc version /{print $3}'`
|
||||
case $GCC_VER in
|
||||
1.*) no_attrib_nonnull=1 ;;
|
||||
2.8* | 2.9*)
|
||||
no_attrib_nonnull=1
|
||||
;;
|
||||
2.*) no_attrib_nonnull=1 ;;
|
||||
*) ;;
|
||||
esac
|
||||
AC_MSG_RESULT([$GCC_VER])
|
||||
|
||||
AC_MSG_CHECKING([if $CC accepts -fno-builtin-memset])
|
||||
saved_CFLAGS="$CFLAGS"
|
||||
@@ -713,7 +724,7 @@ case "$host" in
|
||||
AC_RUN_IFELSE([AC_LANG_SOURCE([[
|
||||
#include <mach-o/dyld.h>
|
||||
#include <stdlib.h>
|
||||
main() { if (NSVersionOfRunTimeLibrary("System") >= (60 << 16))
|
||||
int main() { if (NSVersionOfRunTimeLibrary("System") >= (60 << 16))
|
||||
exit(0);
|
||||
else
|
||||
exit(1);
|
||||
@@ -2812,7 +2823,7 @@ if test "x$openssl" = "xyes" ; then
|
||||
# OpenSSL 3; we use the 1.1x API
|
||||
CPPFLAGS="$CPPFLAGS -DOPENSSL_API_COMPAT=0x10100000L"
|
||||
;;
|
||||
301*)
|
||||
301*|302*)
|
||||
# OpenSSL development branch; request 1.1x API
|
||||
CPPFLAGS="$CPPFLAGS -DOPENSSL_API_COMPAT=0x10100000L"
|
||||
;;
|
||||
@@ -4259,7 +4270,7 @@ dnl test snprintf (broken on SCO w/gcc)
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#ifdef HAVE_SNPRINTF
|
||||
main()
|
||||
int main()
|
||||
{
|
||||
char buf[50];
|
||||
char expected_out[50];
|
||||
@@ -4276,7 +4287,7 @@ main()
|
||||
exit(0);
|
||||
}
|
||||
#else
|
||||
main() { exit(0); }
|
||||
int main() { exit(0); }
|
||||
#endif
|
||||
]])], [ true ], [ AC_DEFINE([BROKEN_SNPRINTF]) ],
|
||||
AC_MSG_WARN([cross compiling: Assuming working snprintf()])
|
||||
|
||||
@@ -111,6 +111,8 @@ static const struct kexalg kexalgs[] = {
|
||||
{ KEX_CURVE25519_SHA256, KEX_C25519_SHA256, 0, SSH_DIGEST_SHA256 },
|
||||
{ KEX_CURVE25519_SHA256_OLD, KEX_C25519_SHA256, 0, SSH_DIGEST_SHA256 },
|
||||
#ifdef USE_SNTRUP761X25519
|
||||
{ KEX_SNTRUP761X25519_SHA512_IANA, KEX_KEM_SNTRUP761X25519_SHA512, 0,
|
||||
SSH_DIGEST_SHA512 },
|
||||
{ KEX_SNTRUP761X25519_SHA512, KEX_KEM_SNTRUP761X25519_SHA512, 0,
|
||||
SSH_DIGEST_SHA512 },
|
||||
#endif
|
||||
|
||||
@@ -63,6 +63,7 @@
|
||||
#define KEX_CURVE25519_SHA256 "curve25519-sha256"
|
||||
#define KEX_CURVE25519_SHA256_OLD "[email protected]"
|
||||
#define KEX_SNTRUP761X25519_SHA512 "[email protected]"
|
||||
#define KEX_SNTRUP761X25519_SHA512_IANA "sntrup761x25519-sha512"
|
||||
|
||||
#define COMP_NONE 0
|
||||
/* pre-auth compression (COMP_ZLIB) is only supported in the client */
|
||||
|
||||
@@ -25,6 +25,7 @@
|
||||
*/
|
||||
|
||||
#define KEX_SERVER_KEX \
|
||||
"sntrup761x25519-sha512," \
|
||||
"[email protected]," \
|
||||
"curve25519-sha256," \
|
||||
"[email protected]," \
|
||||
|
||||
@@ -44,13 +44,15 @@
|
||||
#ifndef HAVE_ARC4RANDOM
|
||||
|
||||
/*
|
||||
* If we're not using a native getentropy, use the one from bsd-getentropy.c
|
||||
* under a different name, so that if in future these binaries are run on
|
||||
* a system that has a native getentropy OpenSSL cannot call the wrong one.
|
||||
* Always use the getentropy implementation from bsd-getentropy.c, which
|
||||
* will call a native getentropy if available then fall back as required.
|
||||
* We use a different name so that OpenSSL cannot call the wrong getentropy.
|
||||
*/
|
||||
#ifndef HAVE_GETENTROPY
|
||||
# define getentropy(x, y) (_ssh_compat_getentropy((x), (y)))
|
||||
int _ssh_compat_getentropy(void *, size_t);
|
||||
#ifdef getentropy
|
||||
# undef getentropy
|
||||
#endif
|
||||
#define getentropy(x, y) (_ssh_compat_getentropy((x), (y)))
|
||||
|
||||
#include "log.h"
|
||||
|
||||
|
||||
@@ -18,8 +18,6 @@
|
||||
|
||||
#include "includes.h"
|
||||
|
||||
#ifndef HAVE_GETENTROPY
|
||||
|
||||
#ifndef SSH_RANDOM_DEV
|
||||
# define SSH_RANDOM_DEV "/dev/urandom"
|
||||
#endif /* SSH_RANDOM_DEV */
|
||||
@@ -52,6 +50,10 @@ _ssh_compat_getentropy(void *s, size_t len)
|
||||
ssize_t r;
|
||||
size_t o = 0;
|
||||
|
||||
#ifdef HAVE_GETENTROPY
|
||||
if (r = getentropy(s, len) == 0)
|
||||
return 0;
|
||||
#endif /* HAVE_GETENTROPY */
|
||||
#ifdef HAVE_GETRANDOM
|
||||
if ((r = getrandom(s, len, 0)) > 0 && (size_t)r == len)
|
||||
return 0;
|
||||
@@ -79,4 +81,3 @@ _ssh_compat_getentropy(void *s, size_t len)
|
||||
#endif /* WITH_OPENSSL */
|
||||
return 0;
|
||||
}
|
||||
#endif /* WITH_GETENTROPY */
|
||||
|
||||
@@ -69,10 +69,6 @@ void closefrom(int);
|
||||
int ftruncate(int filedes, off_t length);
|
||||
#endif
|
||||
|
||||
#if defined(HAVE_DECL_GETENTROPY) && HAVE_DECL_GETENTROPY == 0
|
||||
int _ssh_compat_getentropy(void *, size_t);
|
||||
#endif
|
||||
|
||||
#ifndef HAVE_GETLINE
|
||||
#include <stdio.h>
|
||||
ssize_t getline(char **, size_t *, FILE *);
|
||||
@@ -343,6 +339,7 @@ struct tm *localtime_r(const time_t *, struct tm *);
|
||||
#endif
|
||||
|
||||
#ifndef HAVE_TIMEGM
|
||||
#include <time.h>
|
||||
time_t timegm(struct tm *);
|
||||
#endif
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@ TESTPROGS=closefromtest$(EXEEXT) snprintftest$(EXEEXT) strduptest$(EXEEXT) \
|
||||
|
||||
all: t-exec ${OTHERTESTS}
|
||||
|
||||
%$(EXEEXT): %.c $(LIBCOMPAT)
|
||||
.c: $(LIBCOMPAT)
|
||||
$(CC) $(CFLAGS) $(CPPFLAGS) $(LDFLAGS) -o $@ $< $(LIBCOMPAT) $(LIBS)
|
||||
|
||||
t-exec: $(TESTPROGS)
|
||||
|
||||
@@ -56,6 +56,7 @@ fail(long hver, long lver, int result)
|
||||
int
|
||||
main(void)
|
||||
{
|
||||
#ifdef WITH_OPENSSL
|
||||
unsigned int i;
|
||||
int res;
|
||||
long hver, lver;
|
||||
@@ -67,5 +68,6 @@ main(void)
|
||||
if (ssh_compatible_openssl(hver, lver) != res)
|
||||
fail(hver, lver, res);
|
||||
}
|
||||
#endif
|
||||
exit(0);
|
||||
}
|
||||
|
||||
+11
-1
@@ -32,6 +32,7 @@
|
||||
#include <stdarg.h>
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#include <unistd.h>
|
||||
|
||||
#include "log.h"
|
||||
|
||||
@@ -42,7 +43,16 @@ platform_disable_tracing(int strict)
|
||||
/* On FreeBSD, we should make this process untraceable */
|
||||
int disable_trace = PROC_TRACE_CTL_DISABLE;
|
||||
|
||||
if (procctl(P_PID, 0, PROC_TRACE_CTL, &disable_trace) && strict)
|
||||
/*
|
||||
* On FreeBSD, we should make this process untraceable.
|
||||
* pid=0 means "this process" and but some older kernels do not
|
||||
* understand that, so retry with our own pid before failing.
|
||||
*/
|
||||
if (procctl(P_PID, 0, PROC_TRACE_CTL, &disable_trace) == 0)
|
||||
return;
|
||||
if (procctl(P_PID, getpid(), PROC_TRACE_CTL, &disable_trace) == 0)
|
||||
return;
|
||||
if (strict)
|
||||
fatal("unable to make the process untraceable: %s",
|
||||
strerror(errno));
|
||||
#endif
|
||||
|
||||
@@ -1165,6 +1165,7 @@ character, then the specified algorithms will be placed at the head of the
|
||||
default set.
|
||||
The default is:
|
||||
.Bd -literal -offset indent
|
||||
sntrup761x25519-sha512,
|
||||
[email protected],
|
||||
curve25519-sha256,[email protected],
|
||||
ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,
|
||||
|
||||
+1
-1
@@ -75,7 +75,7 @@ AuthorizedKeysFile .ssh/authorized_keys
|
||||
# be allowed through the KbdInteractiveAuthentication and
|
||||
# PasswordAuthentication. Depending on your PAM configuration,
|
||||
# PAM authentication via KbdInteractiveAuthentication may bypass
|
||||
# the setting of "PermitRootLogin without-password".
|
||||
# the setting of "PermitRootLogin prohibit-password".
|
||||
# If you just want the PAM account and session checks to run without
|
||||
# PAM authentication, then enable this but set PasswordAuthentication
|
||||
# and KbdInteractiveAuthentication to 'no'.
|
||||
|
||||
@@ -956,11 +956,14 @@ ecdh-sha2-nistp384
|
||||
.It
|
||||
ecdh-sha2-nistp521
|
||||
.It
|
||||
sntrup761x25519-sha512
|
||||
.It
|
||||
[email protected]
|
||||
.El
|
||||
.Pp
|
||||
The default is:
|
||||
.Bd -literal -offset indent
|
||||
sntrup761x25519-sha512,
|
||||
[email protected],
|
||||
curve25519-sha256,[email protected],
|
||||
ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,
|
||||
|
||||
Reference in New Issue
Block a user